2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-11045HIGH7.8An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. The Gallery library allow memory corruption ...
CVE-2016-11044HIGH7.8An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The ch...
CVE-2016-11043HIGH7.5An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where...
CVE-2016-11042HIGH7.5An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The S...
CVE-2016-11041MEDIUM4.6An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending ...
CVE-2016-11024CRITICAL9.8odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
CVE-2016-11023CRITICAL9.8odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
CVE-2016-11022HIGH7.2NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code wi...
CVE-2016-1000111MEDIUM5.3Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not pro...
CVE-2016-1487HIGH8.8Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execut...
CVE-2016-6918CRITICAL9.8Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading file...
CVE-2016-1159MEDIUM6.5In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain...
CVE-2016-11021HIGH7.2setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in th...
CVE-2016-11020CRITICAL9.8Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote...
CVE-2016-4606CRITICAL9.8Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrar...
CVE-2016-3182MEDIUM5.5The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of ser...
CVE-2016-3181——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3182. Reason: This candidate is a duplicate of C...
CVE-2016-1000109MEDIUM5.3HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applicat...
CVE-2016-1000005CRITICAL9.8mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if ot...
CVE-2016-1000004CRITICAL9.8Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_d...
CVE-2016-5710MEDIUM4.6NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspeci...
CVE-2016-1544LOW3.3nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
CVE-2016-9928HIGH7.4MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or...
CVE-2016-7524MEDIUM6.5coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil...
CVE-2016-7523MEDIUM6.5coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now